US2002061107A1PendingUtilityA1
Methods and apparatus for implementing a cryptography engine
Priority: Sep 25, 2000Filed: Sep 6, 2001Published: May 23, 2002
Est. expirySep 25, 2020(expired)· nominal 20-yr term from priority
G06F 7/49936H04L 2209/24H04L 2209/125G06F 7/722H04L 63/0428H04L 9/0625H04L 9/12
22
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods and apparatus are provided for implementing a cryptography engine for cryptography processing. A variety of techniques are described. A cryptography engine such as a DES engine running at a clock frequency higher than that of surrounding logic can be synchronized with the surrounding logic using a frequency synchronizer. Sbox logic output can be more efficiently determined by intelligently arranging Sbox input.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A cryptography engine for performing cryptographic operations on a data block, the cryptography engine comprising:
expansion logic configured to expand a first bit sequence into a second bit sequence by moving and duplicating selected bits in the first bit sequence to form a second bit sequence having a length greater than the length of the first bit sequence, the resulting bit sequence having duplicated bits and nonduplicated bits corresponding to a portion of the data block; Sbox logic coupled to the output of expansion logic, wherein nonduplicated bits are selected and provided as inputs to a critical path of the Sbox logic to perform cryptographic operations on the portion of the data block.
2 . The cryptography engine of claim 1 , wherein the Sbox logic comprises a plurality of stages.
3 . The cryptography engine of claim 2 , wherein nonduplicated bits are selected as inputs to a first stage of the Sbox logic.
4 . The cryptography engine of claim 3 , wherein the first stage of the Sbox logic performs a table lookup.
5 . The cryptography engine of claim 2 , wherein the first stage of the Sbox logic is a multiplexer.
6 . The cryptography engine of claim 5 , wherein the second stage of the Sbox logic is a multiplexer.
7 . The cryptography engine of claim 6 , wherein duplicated bits are provided as inputs to the second stage of the Sbox logic.
8 . The cryptography engine of claim 1 , wherein bits 3 and 4 are provided to the critical path of the Sbox logic.
9 . The cryptography engine of claim 1 , wherein the first bit sequence is 6 bits in length.
10 . The cryptography engine of claim 1 , wherein the second bit sequence is 4 bits in length.
11 . A method for performing cryptographic operations on a data block, the method comprising:
providing a first bit sequence to expansion circuitry, the expansion circuitry configured to move and duplicate bits in the first bit sequence to output a second bit sequence having a length greater than the length of the first bit sequence; identifying nonduplicated bits output by the expansion circuitry; providing nonduplicated bits to a first stage of Sbox circuitry; identifying duplicated bits output by the expansion circuitry, wherein duplicated bits correspond to bits in a first bit sequence that are replicated to produce a second bit sequence; providing duplicated bits and the output of the first stage of Sbox circuitry to a second stage of Sbox circuitry, wherein duplicated bits are provided to the second stage of Sbox circuitry after nonduplicated bits are provided to the first stage of Sbox circuitry.
12 . The method of claim 11 , wherein the Sbox circuitry comprises three stages.
13 . The method of claim 12 , wherein the first stage of Sbox circuitry is a case statement.
14 . The method of claim 12 , wherein the first stage of Sbox circuitry performs a table lookup.
15 . The method of claim 12 , wherein the first stage of Sbox circuitry is a multiplexer.
16 . The method of claim 15 , wherein the second stage of Sbox circuitry is a multiplexer.
17 . The method of claim 11 , wherein bits 3 and 4 of a 6 bit block are provided to the first stage of Sbox circuitry.
18 . A cryptography accelerator for performing cryptographic operations on a data block, the cryptography accelerator comprising:
means for providing a first bit sequence to expansion circuitry, the expansion circuitry configured to move and duplicate bits in the first bit sequence to output a second bit sequence having a length greater than the length of the first bit sequence; means for identifying nonduplicated bits output by the expansion circuitry; means for providing nonduplicated bits to a first stage of Sbox circuitry; means for identifying duplicated bits output by the expansion circuitry, wherein duplicated bits correspond to bits in a first bit sequence that are replicated to produce a second bit sequence; means for providing duplicated bits and the output of the first stage of Sbox circuitry to a second stage of Sbox circuitry, wherein duplicated bits are provided to the second stage of Sbox circuitry after nonduplicated bits are provided to the first stage of Sbox circuitry.
19 . The cryptography accelerator of claim 18 , wherein the Sbox circuitry comprises three stages.
20 . The cryptography accelerator of claim 19 , wherein the first stage of Sbox circuitry is a case statement.
21 . The cryptography accelerator of claim 19 , wherein the first stage of Sbox circuitry performs a table lookup.
22 . The cryptography accelerator of claim 19 , wherein the first stage of Sbox circuitry is a multiplexer.
23 . The cryptography accelerator of claim 22 , wherein the second stage of Sbox circuitry is a multiplexer.
24 . The cryptography accelerator of claim 18 , wherein bits 3 and 4 of a 6 bit block are provided to the first stage of Sbox circuitry.
25 . A cryptography accelerator for performing cryptography operations, the cryptography accelerator comprising:
a DES engine; a frequency synchronizer coupled to the DES engine; surrounding logic coupled to the DES engine and the frequency synchronizer, wherein the DES engine operates at a first clock rate and the surrounding logic operates at a second clock rate different from the first clock rate.
26 . The cryptography accelerator of claim 25 , wherein the first clock rate is faster than the second clock rate.
27 . The cryptography accelerator of claim 25 , wherein the frequency synchronizer signals the DES engine to begin performing cryptography operations.
28 . The cryptography accelerator of claim 25 , wherein the frequency synchronizer signals the surrounding logic to read processed data from the DES engine after cryptography operations are performed.
29 . The cryptography accelerator of claim 25 , wherein the frequency synchronizer uses a reference clock associated with the surrounding logic to synchronize a 1×clock and a higher multiple clock associated with the DES engine.
30 . The cryptography accelerator of claim 25 , wherein the negative edge of the 1×clock is used to catch a start signal associated with the reference clock to allow consideration of skew.
31 . The cryptography accelerator of claim 25 , wherein the second positive edge of the 3×clock is used to catch the start signalJoin the waitlist — get patent alerts
Track US2002061107A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.